Add taint step for StringTemplateExpr

This commit is contained in:
Tony Torralba
2022-02-02 11:19:22 +01:00
committed by Ian Lynagh
parent b7914ed77b
commit 6bd6097ed1

View File

@@ -157,6 +157,8 @@ private predicate localAdditionalTaintExprStep(Expr src, Expr sink) {
or
sink.(AssignAddExpr).getSource() = src and sink.getType() instanceof TypeString
or
sink.(StringTemplateExpr).getComponent(_) = src
or
sink.(LogicExpr).getAnOperand() = src
or
constructorStep(src, sink)